Total
6537 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2008-0559 | 1 Nilsons Blogger | 1 Nilsons Blogger | 2024-11-21 | 5.0 MEDIUM | N/A |
Multiple directory traversal vulnerabilities in Nilson's Blogger 0.11 allow remote attackers to include and execute arbitrary local files via a .. (dot dot) in (1) the permalink parameter in core.php, accessed through index.php; and (2) the thispost parameter in comments.php. | |||||
CVE-2008-0545 | 1 Bubbling Library | 1 Bubbling Library | 2024-11-21 | 7.5 HIGH | N/A |
Multiple directory traversal vulnerabilities in Bubbling Library 1.32 allow remote attackers to include and execute arbitrary local files via a .. (dot dot) in the (1) uri parameter to (a) yui-menu.tpl.php, (b) simple.tpl.php, and (c) advanced.tpl.php in dispatcher/framework/; and the (2) page parameter to (d) yui-menu.php, (e) simple.php, and (f) advanced.php in dispatcher/framework/, different vectors than CVE-2008-0521. | |||||
CVE-2008-0542 | 1 Gerd Tentler | 1 Simple Forum | 2024-11-21 | 5.0 MEDIUM | N/A |
Directory traversal vulnerability in thumbnail.php in Gerd Tentler Simple Forum 3.2 allows remote attackers to read arbitrary files via a .. (dot dot) in the file parameter. | |||||
CVE-2008-0521 | 1 Bubbling Library | 1 Bubbling Library | 2024-11-21 | 5.0 MEDIUM | N/A |
Multiple directory traversal vulnerabilities in Bubbling Library 1.32 allow remote attackers to read arbitrary files via a .. (dot dot) in the uri parameter to dispatcher.php in (1) examples/dispatcher/framework/, (2) examples/dispatcher/, (3) examples/wizard/, and (4) PHP/, different vectors than CVE-2008-0545. | |||||
CVE-2008-0513 | 1 Phpcms | 1 Phpcms | 2024-11-21 | 7.8 HIGH | N/A |
Directory traversal vulnerability in parser/include/class.cache_phpcms.php in phpCMS 1.2.2 allows remote attackers to read arbitrary files via a .. (dot dot) in the file parameter to parser/parser.php, as demonstrated by a filename ending with %00.gif, a different vector than CVE-2005-1840. | |||||
CVE-2008-0501 | 1 Sourceforge | 1 Phpmyclub | 2024-11-21 | 5.8 MEDIUM | N/A |
Directory traversal vulnerability in phpMyClub 0.0.1 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the page_courante parameter to the top-level URI. | |||||
CVE-2008-0489 | 1 Clansphere | 1 Clansphere | 2024-11-21 | 5.0 MEDIUM | N/A |
Directory traversal vulnerability in install.php in Clansphere 2007.4.4 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the lang parameter. | |||||
CVE-2008-0488 | 1 Vb Marketing | 1 Vb Marketing | 2024-11-21 | 7.5 HIGH | N/A |
Directory traversal vulnerability in tseekdir.cgi in VB Marketing allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the location parameter. | |||||
CVE-2008-0481 | 1 Web Wiz | 1 Rich Text Editor | 2024-11-21 | 5.0 MEDIUM | N/A |
Directory traversal vulnerability in RTE_file_browser.asp in Web Wiz Rich Text Editor 4.0 allows remote attackers to list arbitrary directories, and .txt and .zip files, via a .....\\\ in the sub parameter in a save action. | |||||
CVE-2008-0480 | 1 Web Wiz | 1 Web Wiz Forums | 2024-11-21 | 5.0 MEDIUM | N/A |
Multiple directory traversal vulnerabilities in Web Wiz Forums 9.07 and earlier allow remote attackers to list arbitrary directories, and .txt and .zip files, via a .....\\\ in the sub parameter to (1) RTE_file_browser.asp or (2) file_browser.asp. | |||||
CVE-2008-0479 | 1 Web Wiz | 1 Newspad | 2024-11-21 | 5.0 MEDIUM | N/A |
Directory traversal vulnerability in RTE_file_browser.asp in Web Wiz NewsPad 1.02 allows remote attackers to list arbitrary directories, and .txt and .zip files, via a .....\\\ in the sub parameter. | |||||
CVE-2008-0478 | 1 Setcms | 1 Setcms | 2024-11-21 | 6.8 MEDIUM | N/A |
Directory traversal vulnerability in index.php in SetCMS 3.6.5 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the set parameter, as demonstrated by sending a certain CLIENT_IP HTTP header in an enter action to index.php, and injecting PHP sequences into files/enter.set, which is then included by index.php. | |||||
CVE-2008-0465 | 1 Seagullproject.org | 1 Seagull | 2024-11-21 | 5.0 MEDIUM | N/A |
Directory traversal vulnerability in optimizer.php in Seagull 0.6.3 allows remote attackers to read arbitrary files via a .. (dot dot) in the files parameter. | |||||
CVE-2008-0464 | 1 Absofort | 1 Aconon Mail Enterprise Sql | 2024-11-21 | 5.0 MEDIUM | N/A |
Directory traversal vulnerability in archiv.cgi in absofort aconon Mail 2007 Enterprise SQL 11.7.0 and Mail 2004 Enterprise SQL 11.5.1 allows remote attackers to read arbitrary files via a .. (dot dot) in the template parameter. | |||||
CVE-2008-0459 | 1 Liquidsilvercms | 1 Liquidsilvercms | 2024-11-21 | 6.8 MEDIUM | N/A |
Directory traversal vulnerability in update/index.php in Liquid-Silver CMS 0.35, when magic_quotes_gpc is disabled, allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the update parameter. | |||||
CVE-2008-0458 | 1 Slaed | 1 Slaed Cms | 2024-11-21 | 6.8 MEDIUM | N/A |
Directory traversal vulnerability in function/sources.php in SLAED CMS 2.5 Lite allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the newlang parameter to index.php. | |||||
CVE-2008-0452 | 1 Siteman | 1 Siteman | 2024-11-21 | 5.0 MEDIUM | N/A |
Directory traversal vulnerability in articles.php in Siteman 1.1.9 allows remote attackers to read arbitrary files via directory traversal sequences in the cat parameter in a viewart action. | |||||
CVE-2008-0435 | 1 Ozjournals | 1 Ozjournals | 2024-11-21 | 5.0 MEDIUM | N/A |
Directory traversal vulnerability in index.php in OZJournals 2.1.1 allows remote attackers to read portions of arbitrary files via a .. (dot dot) in the id parameter in a printpreview action. | |||||
CVE-2008-0431 | 1 Idmos | 1 Idmos Cms | 2024-11-21 | 5.0 MEDIUM | N/A |
Directory traversal vulnerability in administrator/download.php in IDMOS (aka Phoenix) 1.0 allows remote attackers to read arbitrary files via a .. (dot dot) in the fileName parameter. | |||||
CVE-2008-0427 | 1 Bloo | 1 Bloofoxcms | 2024-11-21 | 7.8 HIGH | N/A |
Directory traversal vulnerability in file.php in bloofoxCMS 0.3 allows remote attackers to read arbitrary files via a .. (dot dot) in the file parameter. |